← Back
CWE-89

20,642 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,642)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Authenex
1Authenex Strong Authentication System Server
Apr 29, 2026
Dec 14, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in akeyActivationLogin.do in Authenex Web Management Control in Authenex Strong Authentication System (ASAS) Server 3.1.0.2 and 3.1.0.3 allows remote attackers to execute arbitrary SQL command...Show more
SQL injection vulnerability in akeyActivationLogin.do in Authenex Web Management Control in Authenex Strong Authentication System (ASAS) Server 3.1.0.2 and 3.1.0.3 allows remote attackers to execute arbitrary SQL commands via the username parameter.Show less
1Freedesktop
1Colord
Apr 29, 2026
Dec 10, 2011
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Multiple SQL injection vulnerabilities in (1) cd-mapping-db.c and (2) cd-device-db.c in colord before 0.1.15 allow local users to execute arbitrary SQL commands via vectors related to color devices and (a) device id, (b)...Show more
Multiple SQL injection vulnerabilities in (1) cd-mapping-db.c and (2) cd-device-db.c in colord before 0.1.15 allow local users to execute arbitrary SQL commands via vectors related to color devices and (a) device id, (b) property, or (c) profile id.Show less
2Getpixie
Lucidcrew
2Pixie
Pixie
Apr 29, 2026
Dec 8, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Pixie CMS 1.01 through 1.04 allow remote attackers to execute arbitrary SQL commands via the (1) pixie_user parameter and (2) Referer HTTP header in a request to the default URI.
1Mambo Foundation
1Mambo
Apr 29, 2026
Dec 8, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in administrator/index2.php in Mambo CMS 4.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the zorder parameter.
1Zabbix
1Zabbix
Apr 29, 2026
Dec 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in popup.php in Zabbix 1.8.3 and 1.8.4, and possibly other versions before 1.8.9, allows remote attackers to execute arbitrary SQL commands via the only_hostid parameter.
1Automattic
1Jetpack
Apr 29, 2026
Dec 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Valid
1Tiny Erp
Apr 29, 2026
Dec 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Valid tiny-erp 1.6 and earlier allow remote attackers to execute arbitrary SQL commands via the SearchField parameter in a search action to (1) _partner_list.php, (2) proioncateg...Show more
Multiple SQL injection vulnerabilities in Valid tiny-erp 1.6 and earlier allow remote attackers to execute arbitrary SQL commands via the SearchField parameter in a search action to (1) _partner_list.php, (2) proioncategory_list.php, (3) _rantevou_list.php, (4) syncategory_list.php, (5) synallasomenos_list.php, (6) ypelaton_list.php, and (7) yproion_list.php.Show less
1Adrotateplugin
1Adrotate
Apr 29, 2026
Dec 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in adrotate/adrotate-out.php in the AdRotate plugin 3.6.6, and other versions before 3.6.8, for WordPress allows remote attackers to execute arbitrary SQL commands via the track parameter (aka...Show more
SQL injection vulnerability in adrotate/adrotate-out.php in the AdRotate plugin 3.6.6, and other versions before 3.6.8, for WordPress allows remote attackers to execute arbitrary SQL commands via the track parameter (aka redirect URL).Show less
1Wordpress
1Wordpress Users
Apr 29, 2026
Dec 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in wp-users.php in WordPress Users plugin 1.3 and possibly earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the uid parameter to index.php.
1Hastymail
1Hastymail2
Apr 29, 2026
Nov 30, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Hastymail2 2.1.1 before RC2 allows remote attackers to execute arbitrary commands via the (1) rs or (2) rsargs[] parameter in a mailbox Drafts action to the default URI.
1Eaimproved
1Com Estateagent
Apr 29, 2026
Nov 29, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Estate Agent (com_estateagent) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showEO action to index.php.
1Takeaweb
1Com Timereturns
Apr 29, 2026
Nov 29, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Time Returns (com_timereturns) component 2.0 and possibly earlier versions for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a timereturns ac...Show more
SQL injection vulnerability in the Time Returns (com_timereturns) component 2.0 and possibly earlier versions for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a timereturns action to index.php.Show less
1Tom K
1Forum Userbar Plugin
Apr 29, 2026
Nov 29, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in userbarsettings.php in the Userbar plugin 2.2 for MyBB Forum allows remote attackers to execute arbitrary SQL commands via the image2 parameter.
1Vtiger
1Vtiger Crm
Apr 29, 2026
Nov 28, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Calendar module in vTiger CRM 5.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php.
1Mh Products
1Kleinanzeigenmarkt
Apr 29, 2026
Nov 23, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in search.php in MH Products kleinanzeigenmarkt allows remote attackers to execute arbitrary SQL commands via the c parameter.
1Rsstatic
1Rsstatic
Apr 29, 2026
Nov 23, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in RSStatic allows remote attackers to execute arbitrary SQL commands via the maxarticles parameter.
1Internet Works
1Nus Newssystem
Apr 29, 2026
Nov 23, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Nus.php in NUs Newssystem 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Cmscout
1Cmscout
Apr 29, 2026
Nov 23, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in CMScout 2.0.8 allows remote attackers to execute arbitrary SQL commands via the album parameter in a photos action.
1Alephsystem
1Cms Ariadna
Apr 29, 2026
Nov 23, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in detResolucion.php in CMS Ariadna 1.1 allows remote attackers to execute arbitrary SQL commands via the res_id parameter. NOTE: the provenance of this information is unknown; the details ar...Show more
SQL injection vulnerability in detResolucion.php in CMS Ariadna 1.1 allows remote attackers to execute arbitrary SQL commands via the res_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Alephsystem
1Cms Ariadna
Apr 29, 2026
Nov 23, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in detResolucion.php in CMS Ariadna 1.1 allows remote attackers to execute arbitrary SQL commands via the tipodoc_id parameter.